Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company wants to protect data in transit between an on-premises data center and Amazon S3. Which AWS service should be used to establish a dedicated, encrypted connection?

⚠ Common exam trap

SCS-C02 often tests the misconception that Direct Connect is encrypted by default — candidates must remember that encryption requires an explicit IPsec VPN or MACsec layer on top of the dedicated connection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Direct Connect with an IPsec VPN

AWS Direct Connect alone provides a dedicated private network path but does not encrypt traffic in transit. To achieve both a dedicated connection and encryption, you must pair Direct Connect with an IPsec VPN running over the dedicated link. This combination gives the private, consistent bandwidth of Direct Connect plus the encryption guarantees of IPsec, satisfying the requirement for encrypted data in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Direct Connect without VPN

    Why it's wrong here

    AWS Direct Connect without VPN creates a private, dedicated physical link from your on-premises network to AWS, but it does not configure any encryption of the traffic flowing across that link. The link is isolated from the public internet, yet the data payloads remain in plaintext, so any compromise of the physical path or the intermediate infrastructure could expose sensitive information. Therefore, while it meets the 'dedicated' criterion, it fails to protect data in transit when encryption is a requirement.

  • ✗

    AWS Transit Gateway

    Why it's wrong here

    AWS Transit Gateway is not a connection at all; it is a network transit hub that routes traffic between VPCs, VPNs, and Direct Connect attachments. It enables you to manage many connections centrally but it does not itself provide the physical or encrypted path between an on-premises environment and AWS. Without an underlying transport like Direct Connect or an AWS Site-to-Site VPN, Transit Gateway has no means to carry or protect the data in transit.

  • ✓

    AWS Direct Connect with an IPsec VPN

    Why this is correct

    AWS Direct Connect with an IPsec VPN layers an encrypted VPN tunnel over a dedicated, private Direct Connect connection, giving you both isolation from the public internet and traffic confidentiality. The IPsec protocol authenticates and encrypts the packets, ensuring that data is protected in transit while still benefiting from the predictable latency and throughput of the physical link. This is the recommended pattern when you need both dedicated bandwidth and encryption.

  • ✗

    AWS Site-to-Site VPN over the internet

    Why it's wrong here

    AWS Site-to-Site VPN over the internet leverages an IPsec tunnel to encrypt traffic, but it uses the public internet as the underlying transport. Because the tunnel traverses the internet, it is subject to unpredictable latency, packet loss, and possible congestion, and it does not provide a private, dedicated path between your on-premises network and AWS. While it fulfills the encryption requirement, it fails the 'dedicated' requirement, making it unsuitable for the stated need.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.